Ethical Hacking News
A new breed of wiper malware has emerged, targeting critical Ukrainian infrastructure in a devastating attack. The PathWiper malware, first discovered in June 2025, shares similarities with HermeticWiper (aka FoxBlade, KillDisk, or NEARMISS) and is attributed to a Russia-nexus advanced persistent threat (APT) actor. This latest wave of attacks serves as a stark reminder of the ongoing threat to Ukrainian critical infrastructure despite the longevity of the Russia-Ukraine war.
The cybersecurity landscape has been shaken by the emergence of a highly sophisticated malware strain called PathWiper. The attackers behind PathWiper utilized a legitimate endpoint administration framework to gain access to administrative consoles and issue malicious commands. The attack mechanism employed by PathWiper involves a BAT file that executes a Visual Basic Script, which overwrites files on disk with randomly generated bytes. PathWiper targets several key areas of a Windows system, including the Master Boot Record (MBR) and $MFT, $LogFile, $Boot, $Bitmap, $TxfLog, $Tops, and $AttrDef. The malware shares similarities with HermeticWiper, but differs in the data corruption mechanism used against identified drives and volumes. A new campaign by Silent Werewolf targets Moldovan and Russian companies with malware, using a phishing email with a ZIP file attachment. BO Team, a pro-Ukrainian hacktivist group, has been targeting Russian organizations, using a wide arsenal of malware and exploiting remote access software like AnyDesk.
The cybersecurity landscape has recently been shaken to its core by the emergence of a highly sophisticated and destructive malware strain known as PathWiper. This particular brand of malware, which was first discovered in June 2025, has already made headlines for its brazen attack on critical infrastructure within Ukraine, leaving many to wonder how such a sophisticated threat was able to evade detection for so long.
According to recent findings from Cisco Talos, the attackers behind this latest wave of attacks utilized a legitimate endpoint administration framework to gain access to the administrative console of the targeted entity. This, in turn, allowed them to issue malicious commands and deploy PathWiper across connected endpoints with unprecedented ease. The attack is attributed to a Russia-nexus advanced persistent threat (APT) actor based on the tradecraft observed and overlapping capabilities with destructive malware used in previous attacks against Ukraine.
The attack mechanism employed by PathWiper is nothing short of ingenious, as it utilizes a BAT file that contains a Visual Basic Script (VBScript) file which in turn executes a malicious binary under the name "sha256sum.exe" in the Windows TEMP folder. This binary then proceeds to gather a list of connected storage media, including physical drive names, volume names and paths, and network drive paths before overwriting the contents of the artifacts with randomly generated bytes.
The PathWiper malware is specifically designed to target several key areas of a Windows system, including the Master Boot Record (MBR), $MFT, $MFTMirr, $LogFile, $Boot, $Bitmap, $TxfLog, $Tops, and $AttrDef. Furthermore, it irrevocably destroys files on disk by overwriting them with randomized bytes and attempts to dismount volumes.
The PathWiper malware shares some level of similarity with HermeticWiper (aka FoxBlade, KillDisk, or NEARMISS), which was detected coinciding with Russia's full-scale military invasion of Ukraine in February 2024. While both wipers attempt to corrupt the MBR and NTFS-related artifacts, it bears noting that HermeticWiper and PathWiper differ in the manner the data corruption mechanism is used against identified drives and volumes.
This latest wave of attacks serves as a stark reminder of the ongoing threat to Ukrainian critical infrastructure despite the longevity of the Russia-Ukraine war. The continued evolution of wiper malware variants highlights the need for vigilance and proactive measures to be taken by organizations across the globe to safeguard their systems against such threats.
In related news, Russian cybersecurity company BI.ZONE has uncovered two new campaigns undertaken by Silent Werewolf in March 2025 to infect Moldovan and Russian companies with malware. The attackers employed two separate loader instances to retrieve the malicious payload from their C2 server, unfortunately, the payload itself was not available at the time of this research.
However, a retrospective analysis of similar Silent Werewolf campaigns suggests that the threat actor used XDigo malware. Some of the targets of the attacks include nuclear, aircraft, instrumentation, and mechanical engineering sectors in Russia. The starting point is a phishing email containing a ZIP file attachment that, in turn, includes an LNK file and a nested ZIP archive.
The second ZIP file consists of a legitimate binary, a malicious DLL, and a decoy PDF. Unpacking and launching the Windows shortcut file triggers the extraction of the nested archive and ultimately causes the rogue DLL to be sideloaded via the legitimate executable ("DeviceMetadataWizard.exe").
This DLL is a C# loader ("d3d9.dll") that's designed to retrieve the next-stage payload from a remote server and display the lure document to the victim. The adversaries appear to run checks on target systems, if a target host does not meet certain criteria, the Llama 2 large language model (LLM) in GGUF format is downloaded from hxxps://huggingface[.]co/TheBloke/Llama-2-70B-GGUF/resolve/main/llama-2-70b.Q5_K_M.gguf".
This hinders the comprehensive analysis of the entire attack and allows the threat actor to bypass defenses such as sandboxes. BI.ZONE observed a second campaign that same month targeting unknown sectors in Moldova and, likely, Russia using the same C# loader, but via phishing lures related to official vacation schedules and recommendations for protecting corporate information infrastructure against ransomware attacks.
Furthermore, Russian state-owned companies and organizations spanning technology, telecommunications, and production verticals are also said to have come under cyber assaults from a pro-Ukrainian hacktivist group codenamed BO Team (aka Black Owl, Hoody Hyena, and Lifting Zmiy).
"BO Team is a serious threat aimed both at causing maximum damage to the victim and at extracting financial benefits," Kaspersky researchers said in a report last week, detailing the threat actor's ability to sabotage victim's infrastructure and, in some instances, even resorts to data encryption and extortion.
Armed with remote access, BO Team has been observed destroying file backups, deleting files using the SDelete utility, and additionally dropping the Windows version of the Babuk encryptor to demand a ransom in exchange for regaining access. The group also uses scheduled tasks to set up persistence, assigns malicious component names similar to system or well-known executable files to evade detection, extracts the Active Directory database using ntdsutil, runs various commands to collect information about Telegram, running processes, current users, remote RDP sessions, and antivirus software installed on the endpoints.
BO Team also utilizes RDP and SSH protocols to perform lateral movement within Windows and Linux infrastructures. Furthermore, it drops legitimate remote access software like AnyDesk for command-and-control purposes.
"The BO Team group poses a significant threat to Russian organizations due to its unconventional approach to conducting attacks," Kaspersky said. "Unlike most pro-Ukrainian hacktivist groups, BO Team actively uses a wide arsenal of malware, including backdoors such as BrockenDoor, Remcos, and DarkGate."
"These features confirm the high level of autonomy of the group and the absence of stable connections with other representatives of the pro-Ukrainian hacktivist cluster. In the public activity of BO Team, there are practically no signs of interaction, coordination or exchange of tools with other groups. This once again emphasizes its unique profile within the current hacktivist landscape in Russia."
As the threat landscape continues to evolve at an unprecedented rate, it is imperative for organizations and individuals alike to remain vigilant and proactive in safeguarding their systems against emerging threats such as PathWiper.
In conclusion, recent findings from Cisco Talos have highlighted a critical vulnerability in Ukrainian critical infrastructure due to the deployment of the highly destructive PathWiper malware. As this threat continues to gain traction, it is essential that organizations across the globe take immediate action to bolster their defenses and safeguard against such attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/New-PathWiper-Malware-Unleashes-Devastating-Attacks-on-Critical-Ukrainian-Infrastructure-ehn.shtml
https://thehackernews.com/2025/06/new-pathwiper-data-wiper-malware.html
Published: Fri Jun 6 04:37:54 2025 by llama3.2 3B Q4_K_M